2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-19429CRITICAL9.4Jenkins FilePath.untarFrom() does not validate symlink targets in extracted TAR archives, even in versions patched for C...
CVE-2026-13206CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networ...
CVE-2026-72593CRITICAL9.8A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to acce...
CVE-2026-72592CRITICAL9.8An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to e...
CVE-2026-72590CRITICAL9.8An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker...
CVE-2026-72589CRITICAL9.8An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker...
CVE-2026-72580CRITICAL9.8An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute a...
CVE-2026-72577CRITICAL9.8Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary ...
CVE-2026-72575CRITICAL9.1An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, crea...
CVE-2026-72569CRITICAL9.1A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to d...
CVE-2026-72567CRITICAL9.8An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated rem...
CVE-2026-72565CRITICAL9.8A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-tab...
CVE-2026-72564CRITICAL9.6An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to aut...
CVE-2026-55799CRITICAL9.8Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgra...
CVE-2026-44416CRITICAL9.8Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. U...
CVE-2026-42537CRITICAL9.8Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0...
CVE-2026-40920CRITICAL9.8Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade...
CVE-2026-32227CRITICAL9.8SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to v...
CVE-2026-28672CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. Thi...
CVE-2026-66915CRITICAL10Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute ar...
CVE-2026-19053CRITICAL9.1The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQ...
CVE-2026-16299CRITICAL9.8The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing u...
CVE-2026-16298CRITICAL9.8The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthen...
CVE-2026-19348CRITICAL9.8A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf ...
CVE-2026-18473CRITICAL9.1The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now